Courseiva

CCNA Endpoint Management Questions

36 questions · Endpoint Management · All types, answers revealed

1
MCQmedium

An employee is reporting that they cannot access corporate Gmail on their personal Android device. You have set up 'Advanced mobile management'. What is the most likely cause if the device is showing as 'Blocked' in the Admin console?

A.The device has not been enrolled in the corporate Wi-Fi network
B.The device is pending admin approval in the mobile devices list
C.The user's account is locked in the Admin console
D.The user has not installed the Google Device Policy app
AnswerB

Advanced management often requires manual approval for new devices.

Why this answer

Under Advanced mobile management, devices must be approved by an administrator or meet specific compliance rules before they can sync corporate data.

2
MCQhard

You need to block a specific version of the Chrome browser because of a security vulnerability. Which setting do you use?

A.Device settings > Chrome > Version control
B.Admin console > Security > Browser blocking
C.User settings > Chrome > Update policy
D.Browser settings > Apps and extensions > Version pinning
AnswerD

This allows you to manage which versions are allowed.

Why this answer

Chrome browser management allows you to enforce version policies to ensure users are on secure versions.

3
MCQmedium

You are configuring Endpoint Verification. What is the primary purpose of the Endpoint Verification extension on a user's browser?

A.To collect device information for context-aware access
B.To enable remote wipe capabilities
C.To enforce password complexity
D.To block all malicious websites
AnswerA

The extension reports device state to Google to enable context-aware access policies.

Why this answer

Endpoint Verification collects device metadata (serial number, encryption, OS) and reports it to the Admin console for access context.

4
MCQeasy

Your organization uses ChromeOS devices. You want to enforce a policy that prevents users from using guest mode on these devices. Where do you configure this?

A.Device settings
B.Network settings
C.Users & browsers settings
D.Apps & extensions settings
AnswerA

Guest mode is a device-level setting found under Chrome > Device settings.

Why this answer

ChromeOS device settings are managed under Devices > Chrome > Settings > Device settings.

5
MCQeasy

Where do you go to view a list of all devices currently accessing your organization's data?

A.Reports > Audit > Mobile
B.Directory > Users > Device list
C.Devices > Mobile & endpoints > Devices
D.Security > Devices
AnswerC

This is the inventory page for all managed devices.

Why this answer

The 'Devices' section in the Admin console provides a centralized view of all mobile and desktop devices.

6
Multi-Selecthard

Which THREE settings can be enforced on Android devices using Advanced mobile management?

Select 3 answers
A.Enable the device's GPS tracking
B.Managed application deployment
C.Force an OS update
D.Remote wipe of corporate data
E.Require a screen lock passcode
AnswersB, D, E

Administrators can push and manage apps on Android devices.

Why this answer

Advanced management allows for mandatory passcodes, managed applications, and remote wipe capabilities.

7
MCQhard

You are implementing context-aware access and need to ensure that only devices with a disk-encrypted state are allowed to access Google Drive. Which feature enables this check?

A.Google Workspace Alert Center
B.Device policy profiles
C.Access Levels in Context-Aware Access
D.Chrome Enterprise Upgrade
AnswerC

Access Levels allow you to define rules based on device attributes like disk encryption.

Why this answer

Context-aware access policies use attributes provided by Endpoint Verification to grant or deny access based on device state.

8
MCQeasy

You need to ensure that all corporate-owned Android devices require a screen lock. Where should you configure this setting?

A.Apps > Google Workspace > Android settings
B.Devices > Mobile & endpoints > Settings > Android > Password settings
C.Security > Authentication > Password policy
D.Directory > Users > Security settings
AnswerB

This is the correct path to enforce screen lock requirements for Android devices.

Why this answer

Mobile settings in the Google Admin console are where device security policies like screen lock requirements are defined.

9
MCQhard

Which of the following is true regarding 'Advanced' mobile management for iOS?

A.It replaces the need for an Apple Push Certificate
B.It automatically removes the device after 30 days
C.It allows administrators to manage Wi-Fi profiles and certificates
D.It is required for all Android devices
AnswerC

These are key features of Advanced management for iOS.

Why this answer

Advanced management provides more control, such as certificate management and enterprise Wi-Fi configuration, compared to Basic management.

10
MCQhard

You need to distribute a specific internal Android app to a subset of users. What is the most efficient way to achieve this using Google Workspace?

A.Enable 'Allow all apps' in the mobile device settings
B.Manually install the APK on every user's device
C.Add the app to the Managed Google Play store and assign to an OU
D.Send the APK via email to all employees
AnswerC

This allows for silent installation and controlled app distribution.

Why this answer

Adding the app to the managed Google Play store and assigning it to specific organizational units (OUs) allows for controlled distribution.

11
Multi-Selecthard

Which THREE of the following attributes can be used in Context-Aware Access policies?

Select 3 answers
A.OS version
B.Device encryption status
C.User's favorite browser
D.User's physical GPS location
E.Device management status (Basic/Advanced/Managed)
AnswersA, B, E

This ensures devices are updated and secure.

Why this answer

Device management status, encryption, and OS version are commonly used in access policies.

12
MCQmedium

A user is unable to install a managed app on their iOS device. What is the first thing you should verify?

A.If the user's device is correctly enrolled in device management
B.If the user has updated their iOS version
C.If the App Store is restricted on the device
D.If the user has an iPhone 14 or later
AnswerA

Management status is the prerequisite for app deployment.

Why this answer

If the device is not enrolled or is in an 'Unmanaged' state, managed apps cannot be pushed to it.

13
MCQhard

You want to require that all corporate-owned iOS devices are encrypted. How is this achieved?

A.Enable Advanced Mobile Management for all iOS users
B.Use an MDM profile to force file-level encryption
C.Configure a passcode policy in the iOS device management settings
D.Enable the 'Require disk encryption' setting in iOS mobile settings
AnswerC

Enforcing a passcode on iOS devices ensures the data partition is encrypted.

Why this answer

Apple devices (iOS) are encrypted by default when a passcode is set. Therefore, enforcing a passcode policy effectively enforces encryption.

14
MCQmedium

Your company wants to prevent employees from using personal Google accounts on company-owned ChromeOS devices. Which setting should you enable?

A.User settings > Accounts > Prevent adding accounts
B.Security > Chrome > Account management
C.App management > Block personal accounts
D.Device settings > Sign-in settings > Sign-in restriction
AnswerD

This policy allows you to restrict sign-in to specific domains.

Why this answer

Blocking accounts on managed ChromeOS devices is a standard device policy to prevent data exfiltration.

15
MCQmedium

You need to ensure that Chrome browsers on unmanaged devices are secure. What is a key step to take?

A.Force users to use Incognito mode
B.Use Chrome browser cloud management to enforce policies
C.Require a VPN for all browser traffic
D.Disable all extensions
AnswerB

Cloud management allows you to enforce security policies on browsers.

Why this answer

Enforcing Chrome browser management allows you to apply policies to the browser regardless of the OS of the underlying device.

16
MCQhard

You have a mix of company-owned and BYOD mobile devices. You want to apply different policies to each. What is the recommended strategy?

A.Create two separate OUs and apply different mobile settings to each
B.Create a Google Group and apply policies to the group
C.Use a third-party MDM for the BYOD devices only
D.Create a single OU and use groups for individual device settings
AnswerA

OUs are the standard way to apply granular policies.

Why this answer

Using different Organizational Units (OUs) allows you to apply different MDM policies to different groups of devices or users.

17
Multi-Selecthard

Which THREE of the following are types of reports available in the 'Reports' section of the Admin console regarding mobile devices?

Select 3 answers
A.Device security report
B.Data usage report
C.Mobile audit report
D.User password report
E.Device inventory report
AnswersA, C, E

This shows security status like encryption and passcodes.

Why this answer

Device usage, audit events, and compliance reports are standard reports in Google Workspace.

18
MCQhard

You want to prevent users from copying data from managed apps into personal apps on their mobile devices. Which feature should you configure?

A.Endpoint verification data settings
B.Mobile management > Work profile data sharing settings
C.Context-Aware Access policies
D.Chrome browser management
AnswerB

These settings specifically control data flow between work and personal apps.

Why this answer

Data protection features within mobile management help restrict data movement between work and personal containers.

19
MCQhard

You are setting up Context-Aware Access. You want to deny access to Google Workspace if the device is not encrypted. Which tool identifies the 'is_encrypted' attribute?

A.Device policy controller
B.Endpoint Verification extension
C.Admin console audit logs
D.Google Cloud Identity sync
AnswerB

The extension collects the attribute and sends it to the server.

Why this answer

Endpoint Verification reports device attributes like encryption status back to Google, which Context-Aware Access then uses to evaluate policies.

20
MCQmedium

You need to deploy a specific Android application to a subset of users. What is the correct procedure?

A.Instruct users to download it themselves from the Play Store
B.Upload the APK file to the server and email the link to users
C.Use a third-party MDM integration
D.Use the 'Apps' section in the Admin console to select the app from Managed Google Play and assign it to an OU
AnswerD

This is the standard, supported workflow for app deployment.

Why this answer

You must add the app via the Managed Google Play store and then assign it to the specific Organizational Unit (OU) or group.

21
MCQeasy

What is required for a user to be able to manage their own mobile device in the Google Admin console?

A.User must be in the 'Everyone' group
B.There is no way for a user to manage devices
C.User must have the 'Mobile device manager' role
D.User must be an owner of the device
AnswerC

This administrative role grants the necessary permissions to manage devices.

Why this answer

Users do not manage their devices in the Admin console; that is for administrators only.

22
MCQeasy

A user reports that their Android work profile is no longer syncing corporate emails. As an administrator, which action should you perform first in the Google Admin console to investigate?

A.View the device details in the Device Management section of the Admin console
B.Force a factory reset on the user's device
C.Remove the user from the mobile management organizational unit
D.Disable the user's account in Google Workspace
AnswerA

Viewing device details allows you to see sync status, last sync time, and compliance alerts.

Why this answer

Checking the device status in the Admin console provides immediate insight into sync errors or compliance issues.

23
Multi-Selectmedium

Which TWO of the following are prerequisites for setting up iOS device management?

Select 2 answers
A.Physical access to each device
B.Apple Push Certificate
C.A custom domain name
D.Advanced Mobile Management
E.Android Enterprise registration
AnswersB, D

The certificate is mandatory for communicating with Apple's servers.

Why this answer

An Apple Push Certificate and Advanced Mobile Management are required to manage iOS devices effectively.

24
MCQmedium

You want to ensure that only company-managed ChromeOS devices can access your Google Workspace environment. Which setting should you modify?

A.Device enrollment settings
B.Security center dashboard
C.Chrome browser cloud management settings
D.Context-Aware Access levels
AnswerD

Access levels allow you to filter by 'Managed device' status.

Why this answer

Context-Aware Access allows you to restrict access based on whether the device is managed by the organization.

25
MCQmedium

A user claims their corporate data is not being wiped after they left the company. You previously issued a 'wipe device' command. What should you check to verify the outcome?

A.The Admin console audit log for mobile management
B.The Google Cloud Platform logs
C.The user's account status in the directory
D.The user's Gmail sent items
AnswerA

The audit log records all device commands and their statuses.

Why this answer

The device audit log provides the necessary visibility into whether a command was successfully executed by the server and acknowledged by the device.

26
Multi-Selectmedium

When managing ChromeOS devices, which TWO settings can be configured within the 'Device settings' section of the Admin console?

Select 2 answers
A.User password rotation
B.Browser history retention
C.Auto-update settings
D.Sign-in restrictions
E.Default home page for all users
AnswersC, D

This is a critical device-level setting.

Why this answer

Device settings allow for controlling device-level behaviors like Auto-update and sign-in restrictions.

27
MCQeasy

A user complains that they cannot access their work email. You see the device is marked as 'Blocked' in the Admin console. What should you do?

A.Approve the device in the mobile management list
B.Send a 'Sync' command
C.Factory reset the device
D.Delete the device record
AnswerA

Approving the device restores access to corporate services.

Why this answer

If a device is blocked, changing the status to 'Approved' or 'Unblocked' will restore access.

28
Multi-Selectmedium

Which TWO of the following can be enforced via ChromeOS device settings?

Select 2 answers
A.Forced re-enrollment after factory reset
B.Automatic screen cleaning
C.Restricted sign-in to specific domains
D.Mandatory screen brightness levels
E.Automatic battery calibration
AnswersA, C

This prevents stolen devices from being repurposed.

Why this answer

Enforcing forced re-enrollment and restricted sign-in are core device security policies.

29
MCQmedium

Your organization requires that all iOS devices accessing corporate data be encrypted and have a passcode. You have enabled Google Mobile Management. Which configuration setting should you verify in the Google Admin console to ensure all devices enforce these policies?

A.Use the Google Cloud Directory Sync tool
B.Set up Basic mobile management
C.Enable Chrome browser management for iOS
D.Configure iOS password requirements in Mobile & endpoints > Settings > iOS
AnswerD

This is the correct path for enforcing passcode requirements on iOS devices.

Why this answer

The 'Password requirements' setting under Device > Mobile & endpoints > Settings > iOS ensures that MDM-enforced policies apply to the device.

30
Multi-Selectmedium

Which TWO of the following actions can be performed on an Android device from the Admin console?

Select 2 answers
A.Remote control of the camera shutter
B.Remote removal of the work profile
C.Remote installation of a specific version of Android OS
D.Remote factory reset of the entire device
E.Remote physical battery removal
AnswersB, D

This is a standard MDM feature for BYOD devices.

Why this answer

Wiping an account and checking the device's last sync time are core features of MDM.

31
Multi-Selectmedium

Which TWO of the following methods can be used to enroll Android devices?

Select 2 answers
A.Manually entering the server IP address
B.Physical USB cable connection to the Admin's PC
C.QR code scanning
D.Zero-touch enrollment
E.Installing a third-party root certificate
AnswersC, D

This is a standard enrollment method.

Why this answer

QR code and Zero-touch enrollment are the standard methods for provisioning corporate devices.

32
MCQmedium

You are configuring a 'Work profile' for Android. What is the primary benefit of this setup?

A.It allows the company to see all personal messages
B.It prevents the user from taking photos
C.It forces the user to use a specific launcher
D.It separates work data and apps from personal data on the same device
AnswerD

Separation is the core benefit of the work profile architecture.

Why this answer

Work profiles isolate work data from personal data, ensuring privacy for the user and security for the company.

33
Multi-Selecthard

Which THREE of the following are settings that can be controlled in the Chrome browser for all users?

Select 3 answers
A.Force-installing extensions
B.Forcing a specific font size
C.Enforcing a specific desktop wallpaper
D.Setting the homepage URL
E.Allowing or blocking bookmark sync
AnswersA, D, E

Administrators can force extensions.

Why this answer

Extension installation, homepage URL, and bookmark sync are controllable browser policies.

34
MCQeasy

You want to ensure that only managed Chrome devices can access your organization's Google Workspace data. Which tool should you configure to verify the security posture of the device before allowing access?

A.Google Workspace Migrate
B.Chrome Endpoint Verification
C.Google Cloud Identity
D.Chrome Remote Desktop
AnswerB

Endpoint Verification provides visibility into device security posture.

Why this answer

Endpoint Verification is the tool used to verify device security posture and report it to the Admin console.

35
MCQmedium

A user has left the company. You need to ensure all corporate data is removed from their Android device, but you want to keep their personal data intact. Which action should you take?

A.Disable the user's account in the Admin console
B.Remove the device from the domain
C.Select 'Wipe account' from the device details page
D.Perform a Factory reset
AnswerC

The 'Wipe account' or 'Work wipe' action specifically targets the managed work profile.

Why this answer

A 'Work wipe' removes only the work profile and corporate data from the device, leaving personal data untouched.

36
MCQeasy

An employee lost their company-issued Android device. What is the most effective way to secure the data?

A.Disable the user's account in Active Directory
B.Use the 'Wipe device' command in the Admin console
C.Change the user's password
D.Send an email to the employee to delete the data
AnswerB

This command clears the device, ensuring no corporate or personal data remains.

Why this answer

Performing a 'Wipe account' or 'Wipe device' command removes corporate data or everything from the device remotely.

Ready to test yourself?

Try a timed practice session using only Endpoint Management questions.